Every Pod gets its own IP, reachable without NAT
Kubernetes defines a deliberately simple network model with three rules. Every Pod gets its own IP address. Every Pod can reach every other Pod's IP directly, across nodes, without NAT. And a Pod sees its own address the same way others see it. This flat model removes the port-mapping complexity of early container networking: each Pod is a first-class host on the network.
Kubernetes does not implement this itself. It delegates to a CNI (Container Network Interface) plugin that assigns Pod IPs, sets up routing between nodes, and, for some plugins, enforces NetworkPolicy. The choice differs by platform. On EKS the default AWS VPC CNI gives Pods real VPC IP addresses; on GKE VPC-native clusters Pods get alias IP ranges and Dataplane V2 is built on Cilium; on-prem clusters commonly use Calico or Cilium.
Containers in the same Pod share one network namespace and one IP, so they talk over localhost. That is the mechanical basis of the sidecar pattern. Reveal the rules with the right arrow.
The most important practical consequence: NetworkPolicy is an API object, but enforcement is done by the CNI. Some simple CNIs accept the YAML and enforce nothing. Always confirm that your cluster's CNI supports policies before relying on them.